↑↓ 选择↵ 打开⌫ 切换范围完整搜索

PG.CENTER 连接 PostgreSQL 文档、百科与生态知识。由 Pigsty 维护。

Wiki / SQLSTATE

2F003 — prohibited_sql_statement_attempted

例程中尝试执行被禁止的 SQL 语句,见于 dblink。

英文手册覆盖始于 PostgreSQL 8.1. 来源历史与运行验证各自保留独立版本边界。

当前阅读 PG 18·选择有来源记录的版本

aliases
未知
class name
SQL Routine Exception
condition name
prohibited_sql_statement_attempted
lang
en
sqlstate
2F003

版本定义 PG 18

2F003

速览 {#at-a-glance}

SQLSTATE 2F003 是 SQL Routine Exception 类别中“尝试执行被禁止 SQL 语句”的成员。固定 PostgreSQL 18.6 源码在 dblink 和 postgres_fdw 的不同连接路径中确认了该 ERROR;dblink 还覆盖了结果返回形状不符合 API 要求的路径。

含义 {#meaning}

确认的消息包括 statement returning results not allowed,以及 password or GSSAPI delegated credentials required,后者带有 detail,有些路径还带 hint。postgres_fdw 的 detail 会说明 user mapping,有时 hint 会提到 password_required=false;dblink 使用自己的凭据措辞。由于同一 SQLSTATE 覆盖不同 API,必须保留实际产生者。

消息 {#messages}

确认的消息包括 statement returning results not allowed,以及 password or GSSAPI delegated credentials required,后者带有 detail,有些路径还带 hint。postgres_fdw 的 detail 会说明 user mapping,有时 hint 会提到 password_required=false;dblink 使用自己的凭据措辞。由于同一 SQLSTATE 覆盖不同 API,必须保留实际产生者。

诊断 {#diagnosis}

对于 dblink,确认本地调用是把会返回行的命令用于无结果 API,还是连接凭据检查。对于 postgres_fdw,若消息点名这些对象,就检查 foreign server 连接、user mapping、认证方法以及服务器的 password_required 策略。保留固定 detail/hint,不要把 dblink 和 postgres_fdw 合并成一个笼统 wrapper。

处理 {#response}

修正命令与 API 的搭配,或修正消息点名的连接凭据和 user mapping,然后验证远端操作。远端连接尝试可能尚未完成;重试前要保留远端/本地边界。不要仅因 dblink 或 postgres_fdw 报告 2F003 就改变事务策略。

版本 {#versions}

锁定目录将该条件的已知下界记为 PostgreSQL 7.4;事实块列出已发布快照,源码路径状态仅限于下方固定的 PostgreSQL 18.6 资料。

相关 {#related}

2F000, 38003

来源 {#sources}

可直接阅读固定的 dblink.c 与 postgres_fdw connection.c 路径;完整范围和未解决的运行边界见结构化证据记录。

比较版本

SQLSTATE 证据与已记录的运行版本

claims · identity
{
  "claim_id": "identity",
  "limits": "",
  "method": "Read the fixed errcodes definition row, severity, and macro.",
  "position": 0,
  "runtime": [],
  "sources": [
    "src.errcodes.18.6"
  ],
  "statement": "2F003 is prohibited_sql_statement_attempted in SQLSTATE Class 2F."
}
claims · resolved-path
{
  "claim_id": "resolved-path",
  "limits": "Source confirmation is not a runtime observation in this batch.",
  "method": "Read the complete source context around the resolved report groups.",
  "position": 1,
  "runtime": [],
  "sources": [
    "src.path.0",
    "src.path.1"
  ],
  "statement": "The fixed PostgreSQL 18.6 source contains the report contexts and message variants described on the page."
}
claims · history-boundary
{
  "claim_id": "history-boundary",
  "limits": "Definition presence is not an emitting-path observation.",
  "method": "Compare canonical release facts with the available history boundary.",
  "position": 2,
  "runtime": [],
  "sources": [
    "src.errcodes.18.6"
  ],
  "statement": "Locked release definitions establish catalogue presence from 7.4; they do not establish a precise introducing release or runtime use."
}
messages · message.dblink-results-not-allowed
{
  "limits": "This is dblink no-result API enforcement.",
  "message_id": "message.dblink-results-not-allowed",
  "path": "",
  "position": 0,
  "raw": {
    "id": "message.dblink-results-not-allowed",
    "limits": "This is dblink no-result API enforcement.",
    "primary_template": "statement returning results not allowed",
    "severity_source": "ERROR",
    "sources": [
      "src.path.0"
    ],
    "sqlstate": "2F003"
  },
  "severity": "ERROR",
  "sources": [
    "src.path.0"
  ],
  "templates": [
    {
      "kind": "primary",
      "literal": "statement returning results not allowed",
      "position": 0,
      "role": "",
      "template": "statement returning results not allowed"
    }
  ]
}
messages · message.dblink-credentials-with-hint
{
  "limits": "Credential wording and whether HINT is present vary by dblink connection path.",
  "message_id": "message.dblink-credentials-with-hint",
  "path": "",
  "position": 1,
  "raw": {
    "detail_template": "Non-superusers may only connect using credentials they provide, eg: password in connection string or delegated GSSAPI credentials",
    "hint_template": "Ensure provided credentials match target server's authentication method.",
    "id": "message.dblink-credentials-with-hint",
    "limits": "Credential wording and whether HINT is present vary by dblink connection path.",
    "primary_template": "password or GSSAPI delegated credentials required",
    "severity_source": "ERROR",
    "sources": [
      "src.path.0"
    ],
    "sqlstate": "2F003"
  },
  "severity": "ERROR",
  "sources": [
    "src.path.0"
  ],
  "templates": [
    {
      "kind": "primary",
      "literal": "password or GSSAPI delegated credentials required",
      "position": 0,
      "role": "",
      "template": "password or GSSAPI delegated credentials required"
    },
    {
      "kind": "detail",
      "literal": "Non-superusers may only connect using credentials they provide, eg: password in connection string or delegated GSSAPI credentials",
      "position": 1,
      "role": "",
      "template": "Non-superusers may only connect using credentials they provide, eg: password in connection string or delegated GSSAPI credentials"
    },
    {
      "kind": "hint",
      "literal": "Ensure provided credentials match target server's authentication method.",
      "position": 2,
      "role": "",
      "template": "Ensure provided credentials match target server's authentication method."
    }
  ]
}
messages · message.dblink-credentials-no-hint
{
  "limits": "This dblink credential branch has DETAIL but no HINT.",
  "message_id": "message.dblink-credentials-no-hint",
  "path": "",
  "position": 2,
  "raw": {
    "detail_template": "Non-superusers must provide a password in the connection string or send delegated GSSAPI credentials.",
    "id": "message.dblink-credentials-no-hint",
    "limits": "This dblink credential branch has DETAIL but no HINT.",
    "primary_template": "password or GSSAPI delegated credentials required",
    "severity_source": "ERROR",
    "sources": [
      "src.path.0"
    ],
    "sqlstate": "2F003"
  },
  "severity": "ERROR",
  "sources": [
    "src.path.0"
  ],
  "templates": [
    {
      "kind": "primary",
      "literal": "password or GSSAPI delegated credentials required",
      "position": 0,
      "role": "",
      "template": "password or GSSAPI delegated credentials required"
    },
    {
      "kind": "detail",
      "literal": "Non-superusers must provide a password in the connection string or send delegated GSSAPI credentials.",
      "position": 1,
      "role": "",
      "template": "Non-superusers must provide a password in the connection string or send delegated GSSAPI credentials."
    }
  ]
}
messages · message.postgres-fdw-password-required
{
  "limits": "User mapping, authentication method, and password_required setting are deployment-dependent.",
  "message_id": "message.postgres-fdw-password-required",
  "path": "",
  "position": 3,
  "raw": {
    "detail_template": "Non-superuser cannot connect if the server does not request a password or use GSSAPI with delegated credentials.",
    "hint_template": "Target server's authentication method must be changed or password_required=false set in the user mapping attributes.",
    "id": "message.postgres-fdw-password-required",
    "limits": "User mapping, authentication method, and password_required setting are deployment-dependent.",
    "primary_template": "password or GSSAPI delegated credentials required",
    "severity_source": "ERROR",
    "sources": [
      "src.path.1"
    ],
    "sqlstate": "2F003"
  },
  "severity": "ERROR",
  "sources": [
    "src.path.1"
  ],
  "templates": [
    {
      "kind": "primary",
      "literal": "password or GSSAPI delegated credentials required",
      "position": 0,
      "role": "",
      "template": "password or GSSAPI delegated credentials required"
    },
    {
      "kind": "detail",
      "literal": "Non-superuser cannot connect if the server does not request a password or use GSSAPI with delegated credentials.",
      "position": 1,
      "role": "",
      "template": "Non-superuser cannot connect if the server does not request a password or use GSSAPI with delegated credentials."
    },
    {
      "kind": "hint",
      "literal": "Target server's authentication method must be changed or password_required=false set in the user mapping attributes.",
      "position": 2,
      "role": "",
      "template": "Target server's authentication method must be changed or password_required=false set in the user mapping attributes."
    }
  ]
}
messages · message.postgres-fdw-scram-pass-through
{
  "limits": "This branch has DETAIL and no HINT.",
  "message_id": "message.postgres-fdw-scram-pass-through",
  "path": "",
  "position": 4,
  "raw": {
    "detail_template": "Non-superusers must delegate GSSAPI credentials, provide a password, or enable SCRAM pass-through in user mapping.",
    "id": "message.postgres-fdw-scram-pass-through",
    "limits": "This branch has DETAIL and no HINT.",
    "primary_template": "password or GSSAPI delegated credentials required",
    "severity_source": "ERROR",
    "sources": [
      "src.path.1"
    ],
    "sqlstate": "2F003"
  },
  "severity": "ERROR",
  "sources": [
    "src.path.1"
  ],
  "templates": [
    {
      "kind": "primary",
      "literal": "password or GSSAPI delegated credentials required",
      "position": 0,
      "role": "",
      "template": "password or GSSAPI delegated credentials required"
    },
    {
      "kind": "detail",
      "literal": "Non-superusers must delegate GSSAPI credentials, provide a password, or enable SCRAM pass-through in user mapping.",
      "position": 1,
      "role": "",
      "template": "Non-superusers must delegate GSSAPI credentials, provide a password, or enable SCRAM pass-through in user mapping."
    }
  ]
}
sources · src.errcodes.18.6
{
  "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
  "docs_url": "",
  "kind": "upstream_source",
  "location": "",
  "path": "src/backend/utils/errcodes.txt",
  "position": 0,
  "sha256": "6e8de346643ba84aa3c9c6a73360acfc7b2dfb89162c06c08ce9bf5bcd5bbcba",
  "source_id": "src.errcodes.18.6",
  "tag": "REL_18_6",
  "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/src/backend/utils/errcodes.txt#L291"
}
sources · src.path.0
{
  "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
  "docs_url": "",
  "kind": "upstream_source",
  "location": "",
  "path": "contrib/dblink/dblink.c",
  "position": 1,
  "sha256": "e4cfaec3a0a1e5d23fded584725e0f6cf7a17321ad99e5fe046e8b7f97416f15",
  "source_id": "src.path.0",
  "tag": "REL_18_6",
  "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/contrib/dblink/dblink.c#L1488"
}
sources · src.path.1
{
  "commit": "724edf9bde9d356724ad384a2e196edc3c9f80f7",
  "docs_url": "",
  "kind": "upstream_source",
  "location": "",
  "path": "contrib/postgres_fdw/connection.c",
  "position": 2,
  "sha256": "67fc002657f2c7df6d93cbf99c933cbc103907d1857ed77aedbb85099ea4dda0",
  "source_id": "src.path.1",
  "tag": "REL_18_6",
  "url": "https://github.com/postgres/postgres/blob/724edf9bde9d356724ad384a2e196edc3c9f80f7/contrib/postgres_fdw/connection.c#L756"
}
sources · src.calls.REL_18_6
{
  "commit": "",
  "docs_url": "",
  "kind": "local_artifact",
  "location": "",
  "path": "raw/calls/REL_18_6.jsonl",
  "position": 3,
  "sha256": "9ee8a0e81d8f0825c5c1ae45583439859a26e602bdd4ce2f2a62aa278867ccbf",
  "source_id": "src.calls.REL_18_6",
  "tag": "",
  "url": ""
}

来源引用

完整定义与证据 JSON

定义来源

center · PostgreSQL 18 · english-manuals:38f3e76e1145418e772fc5c4c480ef60a1136f9ab451136c0a9fd2ece756332a

正文语言: zh-Hans · english-manuals:38f3e76e1145418e772fc5c4c480ef60a1136f9ab451136c0a9fd2ece756332a